CySEC Circular C790: ML/TF Risks After MiCA Transitional Period Requirements & Compliance Guide
Introduction
The Cyprus Securities and Exchange Commission (CySEC) issued Circular C790 on 7 July 2026, addressing Regulated Entities affected by the end of the MiCA Transitional Period on 1 July 2026. This circular is a reminder of existing obligations for compliance following this significant regulatory shift.
CySEC Circular C790 – At a Glance
- Issued date: 7 July 2026
- Applies to: Regulated Entities, including Crypto Asset Service Providers
- Deadline: [CONFIRM]
- Key requirement: Firms must obtain MiCAR authorisation and manage ML/TF risks.
- Submission method: [CONFIRM]
What Does This Circular Require?
What firms must do. Firms must enhance AML/CFT controls, complete risk assessments, and update customer due diligence.
Legal basis. Prevention and Suppression of Money Laundering Activities Law (L. 188(I) 2007)
Regulatory objective. Ensure the integrity of the EU financial system by managing ML/TF risks.
Who Is in Scope?
This guidance applies to all Regulated Entities involved in crypto-asset services within the EU.
- Crypto Asset Service Providers
- CIFs
- UCITS Management Companies
- Internally managed UCITS
- AIFMs
- Internally managed AIFs
- Internally managed AIFLNPs
- Companies managing AIFLNPs
- Small AIFMs
These entities must adhere to MiCAR and related AML/TF laws.
Edge cases and exceptions:
- Unauthorised VASPs: Wind-down risk
- Authorised CASPs: Scalability of AML/CFT controls
Key Requirements Breakdown
Reporting / Submission Requirements
Maintain up-to-date CDD and report suspicious activities.
Technical / System Requirements
Transaction monitoring systems must handle increased transaction volumes.
Validation or Approval Process
Strengthen onboarding and risk integration processes.
Practical Implementation: What Firms Should Do
In practice, authorised CASPs should ensure their AML/CFT systems are robust enough to handle the influx of customers from unauthorised VASPs. This includes individual risk assessments and avoiding blanket de-risking practices. Unauthorised VASPs must implement effective wind-down procedures while maintaining compliance with AML/CFT obligations.
How to Apply This Correctly
- Enhance AML/CFT controls and resources.
- Conduct individual risk assessments for migrating customers.
- Update transaction monitoring systems to handle increased volumes.
- Ensure compliance with FATF guidance on offshore VASPs.
Compliance Officer Checklist
- Review and update AML/CFT policies.
- Conduct staff training on new processes.
- Establish wind-down plans for unauthorised VASPs.
- Implement enhanced customer due diligence practices.
Evidence to Retain
- Updated customer due diligence records
- Transaction monitoring reports
- AML/CFT compliance audits
Why This Matters
Failure to comply with the regulatory obligations following the MiCA Transitional Period may expose firms to heightened ML/TF risks and regulatory actions. It is crucial for the integrity and security of the EU financial system that all entities adapt their processes to meet the new standards and safeguard their operations.
Frequently Asked Questions
What is the MiCA Transitional Period?
The MiCA Transitional Period allowed firms time to comply with the new Markets in Crypto-Assets Regulation. It ended on 1 July 2026, requiring CASPs to obtain authorization.
Who does this circular apply to?
This circular applies to Regulated Entities, including Crypto Asset Service Providers, CIFs, and various types of management companies managing investment funds in Cyprus.
What must unauthorised VASPs do following the end of the transitional period?
Unauthorised VASPs must implement robust wind-down procedures, maintain updated CDD information, and comply with AML/CFT obligations until all regulated activities have ceased.
How should authorised CASPs handle increased ML/TF risks?
Authorised CASPs should ensure their transaction monitoring systems are scalable to manage increased volumes and conduct thorough individual risk assessments for new customers migrating from unauthorised VASPs.
What should entities do to mitigate risks with offshore VASPs?
Entities should identify and assess ML/TF risks in relationships with offshore VASPs and apply risk mitigation measures based on a risk-based approach as outlined by the FATF.
How CX Financia Can Support You
CX Financia can assist with Regulatory Compliance and AML/CFT obligations, helping firms effectively manage the transition and implement robust processes. Contact us for further support in ensuring compliance post-MiCA Transitional Period.
Disclaimer
General information, not regulatory advice…
